{"id":2424,"date":"2019-04-26T05:39:33","date_gmt":"2019-04-26T05:39:33","guid":{"rendered":"https:\/\/www.bizlegal.eu\/?page_id=2424"},"modified":"2019-04-26T05:41:20","modified_gmt":"2019-04-26T05:41:20","slug":"navigating-gdpr-5-common-mistakes-in-a-privacy-policy%ef%bb%bf","status":"publish","type":"page","link":"https:\/\/www.bizlegal.eu\/?page_id=2424","title":{"rendered":"Navigating GDPR: 5 Common mistakes in  a Privacy policy\ufeff"},"content":{"rendered":"\n<p>Business Legal is often called in to help\nbusinesses review or establish good GDPR practice, David Fagan and I help\nbusinesses of all sizes navigate this complex area and despite the GDPR having\nbeen in place now for over 10 months, from small start-ups to prospering SME\u2019s\nthere are still plenty of businesses that are struggling to comply. <\/p>\n\n\n\n<p>So as we approach the anniversary of its\nintroduction, I thought I would share some of the common mistakes we see around\na &nbsp;privacy policy. Whilst I could easily\nhave made the list significantly longer, I wanted to make sure the article\ndidn\u2019t run to multiple pages, and also make it a manageable start-point for\nbusinesses looking to comply with this important legislation.<\/p>\n\n\n\n<ol><li><strong>The policy scope<\/strong>. &nbsp;A simple one to start with, \nand also most common \u2013 the policy should not only refer to the data \nprocessed on the website site but to all the services provided to the \ncustomers and the processing required for them.<\/li><li><strong>Disclosure of personal data<\/strong>.\n Everyone swears they do not share the data with unauthorized entities \nand obviously they do not sell them. What they \u201cforget\u201d to mention is \nexactly what data is disclosed and to whom. The biggest problem is that \noften they do not even know or realise themselves that using third-party\n platforms, tools or services means disclosing personal data (for \nexample Internet providers, hosting services, social media platforms, \npayment services online, as well as all entities that have third party \ncookies on their site, as well as their partners). The rule here is \nsimple \u2013 check every touchpoint for the data to build a full picture and\n if you don\u2019t have that expertise or resource in house, bring in a \nconsultant that does.<\/li><li><strong>Data transfers outside the EU \/ EEA<\/strong>&nbsp;and\n protection measures \u2013 must be specified.. Most times, in the case of \ncompanies belonging to a group, they do not even mention the countries \nwhere the transfer is made within the groups \u2026 for example, if the IT \nservices at group level are in &nbsp;India or Turkey &nbsp;ie outside of the EEA.,\n this is often not mentioned, although there is a transfer of almost all\n personal data within the group through its It services.   One solution \nis applying BCRs(binding corporate rules) , which form a legally binding\n internal code of conduct operating within a multinational group, which \napplies to transfers of personal data from the group\u2019s EEA entities to \nthe group\u2019s non-EEA entities. . BCRs are legally binding data protection\n rules with enforceable data subject rights contained in them, which are\n approved by the competent Data Protection Authority.&nbsp; Another solution \nis intra group model clause agreements.<\/li><li><strong>Consent<\/strong>&nbsp;\u2013\n This is often where companies I help think they have a bullet-proof \nsolution but have actually failed to think about the entire set of \nrequirements that GDPR demands. It Is not enough to say \u201cWe have \nrequested the customer\u2019s agreement and have proof that he\/she has \nagreed.\u201d For consent to be valid &nbsp;it must be explicit, informed and \nfreely given. Is consent buried in a largedocument referring generally \nto a multiplicity of types of processingvalid.? It is a requirement to \nbe transparent (i.e. to clearly and precisely tell the individual how \nhis data is going to be proceesed) to do otherwise is a violation of the\n GDPR principles.<\/li><li><strong>Security&nbsp;<\/strong>or&nbsp;<strong>integrity and confidentiality&nbsp;of personal data<\/strong>\n \u2013 &nbsp;taking \u201cappropriate\u201d technical or organisational measures. Those \nappropriate measures should at the very least make sure that the website\n has an SSL certificate, as the organisations invariably send sensitive \npersonal information on insecure channels otherwise. Another appropriate\n measure that is often underdeployed, is encryption.<\/li><\/ol>\n\n\n\n<p>Whilst\nthis is not an exhaustive list, it is a useful prompt to review some of the\nbiggest pitfalls that we at Business Legal regularly come across; And whilst\nBrexit still lacks clarity, what is absolutely clear from recent high profile\ncases across the EU, is that the compliance requirements &nbsp;for GDPR are crystal clear. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Business Legal is often called in to help businesses review or establish good GDPR practice, David Fagan and I help businesses of all sizes navigate this complex area and despite the GDPR having been in place now for over 10 months, from small start-ups to prospering SME\u2019s there are still plenty of businesses that are &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/www.bizlegal.eu\/?page_id=2424\"> <span class=\"screen-reader-text\">Navigating GDPR: 5 Common mistakes in  a Privacy policy\ufeff<\/span> Read More &raquo;<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":""},"coauthors":[],"author_meta":{"author_link":"https:\/\/www.bizlegal.eu\/?author=3","display_name":"Sharon McGauley"},"relative_dates":{"created":"Posted 7 years ago","modified":"Updated 7 years ago"},"absolute_dates":{"created":"Posted on 26\/04\/2019","modified":"Updated on 26\/04\/2019"},"absolute_dates_time":{"created":"Posted on 26\/04\/2019 5:39 am","modified":"Updated on 26\/04\/2019 5:41 am"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2424"}],"collection":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2424"}],"version-history":[{"count":2,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2424\/revisions"}],"predecessor-version":[{"id":2427,"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=\/wp\/v2\/pages\/2424\/revisions\/2427"}],"wp:attachment":[{"href":"https:\/\/www.bizlegal.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}